Web en construccion IndianWebs Security & Risk Analysis

wordpress.org/plugins/web-en-construccion-indianwebs

Pon un mensaje de web en construcción en tu sitio web.

100 active installs v1.0 PHP + WP 3.2+ Updated Sep 16, 2020
coming-soon-pagepagina-en-construccionpagina-en-matenimientounder-construction-pageweb-en-construccion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Web en construccion IndianWebs Safe to Use in 2026?

Generally Safe

Score 85/100

Web en construccion IndianWebs has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "web-en-construccion-indianwebs" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no known CVEs, a limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and 100% of its SQL queries utilize prepared statements. It also performs nonce checks on some operations, which is a positive security measure.

However, the analysis reveals significant concerns, particularly regarding output escaping. A substantial 66% of output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis shows two flows with unsanitized paths, which could potentially lead to file system or other path-related vulnerabilities if these paths are user-controlled. The complete absence of capability checks on any code indicates that sensitive operations, if any exist, are not adequately protected by WordPress's role-based access control system.

The plugin's vulnerability history is clean, showing no past CVEs. While this is generally a good sign, it does not negate the risks identified in the static code analysis. The lack of historical issues could simply mean the plugin hasn't been thoroughly audited for certain types of vulnerabilities, or that its limited functionality hasn't attracted attackers. The overall conclusion is that while the plugin has a small attack surface and uses prepared statements, the prevalent unescaped output and unsanitized paths present critical security risks that require immediate attention.

Key Concerns

  • High percentage of unescaped output
  • Flows with unsanitized paths found
  • No capability checks implemented
Vulnerabilities
None known

Web en construccion IndianWebs Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Web en construccion IndianWebs Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
38
20 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

34% escaped58 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
en_construccion_action (en_construccion.php:56)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Web en construccion IndianWebs Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuen_construccion.php:24
actionwp_enqueue_scriptsen_construccion.php:273
actionwp_headen_construccion.php:335
actionadmin_menutrunk\en_construccion.php:24
actionwp_enqueue_scriptstrunk\en_construccion.php:273
actionwp_headtrunk\en_construccion.php:335
Maintenance & Trust

Web en construccion IndianWebs Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 16, 2020
PHP min version
Downloads19K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Web en construccion IndianWebs Developer Profile

IndianWebs

4 plugins · 400 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Web en construccion IndianWebs

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/web-en-construccion-indianwebs/style.css/wp-content/plugins/web-en-construccion-indianwebs/preview.php
Version Parameters
web-en-construccion-indianwebs/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Web en construccion IndianWebs